tips:vpn:galileo

This is an old revision of the document!


VPN Galileo

Server certificate

ca.crt
-----BEGIN CERTIFICATE-----
MIIE3zCCA8egAwIBAgIJAKI/infDrLAoMA0GCSqGSIb3DQEBCwUAMIGlMQswCQYD
VQQGEwJJVDELMAkGA1UECBMCVlIxDzANBgNVBAcTBlZlcm9uYTEQMA4GA1UEChMH
R2FsaWxlbzEQMA4GA1UECxMHR2FsaWxlbzETMBEGA1UEAxMKR2FsaWxlbyBDQTEQ
MA4GA1UEKRMHRWFzeVJTQTEtMCsGCSqGSIb3DQEJARYec3RlZmFuby5zY2lwaW9u
aUBjc2dhbGlsZW8ub3JnMB4XDTE3MDMyMjE1MDQ0NFoXDTI3MDMyMDE1MDQ0NFow
gaUxCzAJBgNVBAYTAklUMQswCQYDVQQIEwJWUjEPMA0GA1UEBxMGVmVyb25hMRAw
DgYDVQQKEwdHYWxpbGVvMRAwDgYDVQQLEwdHYWxpbGVvMRMwEQYDVQQDEwpHYWxp
bGVvIENBMRAwDgYDVQQpEwdFYXN5UlNBMS0wKwYJKoZIhvcNAQkBFh5zdGVmYW5v
LnNjaXBpb25pQGNzZ2FsaWxlby5vcmcwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
ggEKAoIBAQDgxKb1DORrR5kZhTz1oj4ronvQaU8oyBc71y5oxp70XwIEQkW+87WT
lgfeT8fwqec6KIjQr6SJOhMmIDphYifN1gwseJ4rtLf33WZOsWgWNOeLjxcn354g
M26pWJt3ETP3THUu4dK4Y6T7t7dFJiaIZ0jRg15EIKHsfMZDYRtcl5Sc0EBw4G32
TndnWsy+vJRocM0zkniuDnNnI1GJh3MOLK+/nskOAJO22+vmYJcE3fMsjho2zJgB
qUteWn5pBZm91Q2KQa5W5OQYVNPA4wbopQHxhhEXGDDwm+iQsqjBQVK39TQDwBGS
foMxbPZwr17pJGbhhHGVNm8DP+XnTltFAgMBAAGjggEOMIIBCjAdBgNVHQ4EFgQU
6kM1PEOCDJ+cqiazQu70mrXni+AwgdoGA1UdIwSB0jCBz4AU6kM1PEOCDJ+cqiaz
Qu70mrXni+ChgaukgagwgaUxCzAJBgNVBAYTAklUMQswCQYDVQQIEwJWUjEPMA0G
A1UEBxMGVmVyb25hMRAwDgYDVQQKEwdHYWxpbGVvMRAwDgYDVQQLEwdHYWxpbGVv
MRMwEQYDVQQDEwpHYWxpbGVvIENBMRAwDgYDVQQpEwdFYXN5UlNBMS0wKwYJKoZI
hvcNAQkBFh5zdGVmYW5vLnNjaXBpb25pQGNzZ2FsaWxlby5vcmeCCQCiP4p3w6yw
KDAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQAYkF8O1NFJD0G5bJNn
hy4R7qStYnbELKFosI1KJ4Oz+ibYZxAOCOyURpacJq9NPYAS/P8SA4lHDjhe3ZIq
kNGq1ZxCHIsGWhagHFDHru2ct4nKtyEFSAzzy7UAnQITeTBZkEjDENWncdb41+VA
fJRoM8O1kj3+Kn0Zpwn126pp8/at3oyC4RMXM2FEztege5J93ZfogW/MuNyL4Jlv
iCGKzo/9UtjUGiHbuxUv7SimWYB4OAhrYR1t0sMLLJU7Bu012PEmxeyK6G1zJuBC
3/YQ9xlWkXlbp1E03OvBMCRp1AnJRsznZATBB4xnJ55ZPG6tEqCVS72j2fKMnCa2
vlW7
-----END CERTIFICATE-----
sudo apt install network-manager-openvpn-gnome
sudo service network-manager restart

add VPN connection with network manager GUI:

  • type: openvpn
  • gateway: vpn.csgalileo.org
  • user: <user>
  • pass: <pass>
  • CA certificate: <ca.crt>
  • in advanced settings check “Use TCP connection”
  • in route add 10.0.0.0/8 and 185.91.188.0/25
sudo apt install openvpn
auth.cfg
<user>
<pass>
openvpn.conf
client
remote vpn.csgalileo.org 1194 
auth-user-pass auth.cfg 
ca ca.crt
 
route 10.0.0.0/8 vpn_gateway 3
route 185.91.188.32 255.255.255.224 vpn_gateway 3
route 185.91.188.64 255.255.255.224 vpn_gateway 3
dev tun
proto tcp-client
remote-cert-tls server
persist-tun
persist-key
auth-nocache
go
sudo openvpn --config openvpn.conf

Connect with

./go
c:\Program Files\OpenVPN\config\auth_galileo.cfg
username
password
c:\Program Files\OpenVPN\config\galileo.ovpn
client
dev tun
proto tcp-client
remote-cert-tls server
 
remote vpn.csgalileo.org 1194
route 10.0.0.0 255.0.0.0 vpn_gateway 3
route 185.91.188.0 255.255.255.0 vpn_gateway 3
 
resolv-retry infinite
nobind
persist-key
persist-tun
verb 3
auth-user-pass auth_galileo.cfg
script-security 3
<ca>
-----BEGIN CERTIFICATE-----
MIIE3zCCA8egAwIBAgIJAKI/infDrLAoMA0GCSqGSIb3DQEBCwUAMIGlMQswCQYD
VQQGEwJJVDELMAkGA1UECBMCVlIxDzANBgNVBAcTBlZlcm9uYTEQMA4GA1UEChMH
R2FsaWxlbzEQMA4GA1UECxMHR2FsaWxlbzETMBEGA1UEAxMKR2FsaWxlbyBDQTEQ
MA4GA1UEKRMHRWFzeVJTQTEtMCsGCSqGSIb3DQEJARYec3RlZmFuby5zY2lwaW9u
aUBjc2dhbGlsZW8ub3JnMB4XDTE3MDMyMjE1MDQ0NFoXDTI3MDMyMDE1MDQ0NFow
gaUxCzAJBgNVBAYTAklUMQswCQYDVQQIEwJWUjEPMA0GA1UEBxMGVmVyb25hMRAw
DgYDVQQKEwdHYWxpbGVvMRAwDgYDVQQLEwdHYWxpbGVvMRMwEQYDVQQDEwpHYWxp
bGVvIENBMRAwDgYDVQQpEwdFYXN5UlNBMS0wKwYJKoZIhvcNAQkBFh5zdGVmYW5v
LnNjaXBpb25pQGNzZ2FsaWxlby5vcmcwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
ggEKAoIBAQDgxKb1DORrR5kZhTz1oj4ronvQaU8oyBc71y5oxp70XwIEQkW+87WT
lgfeT8fwqec6KIjQr6SJOhMmIDphYifN1gwseJ4rtLf33WZOsWgWNOeLjxcn354g
M26pWJt3ETP3THUu4dK4Y6T7t7dFJiaIZ0jRg15EIKHsfMZDYRtcl5Sc0EBw4G32
TndnWsy+vJRocM0zkniuDnNnI1GJh3MOLK+/nskOAJO22+vmYJcE3fMsjho2zJgB
qUteWn5pBZm91Q2KQa5W5OQYVNPA4wbopQHxhhEXGDDwm+iQsqjBQVK39TQDwBGS
foMxbPZwr17pJGbhhHGVNm8DP+XnTltFAgMBAAGjggEOMIIBCjAdBgNVHQ4EFgQU
6kM1PEOCDJ+cqiazQu70mrXni+AwgdoGA1UdIwSB0jCBz4AU6kM1PEOCDJ+cqiaz
Qu70mrXni+ChgaukgagwgaUxCzAJBgNVBAYTAklUMQswCQYDVQQIEwJWUjEPMA0G
A1UEBxMGVmVyb25hMRAwDgYDVQQKEwdHYWxpbGVvMRAwDgYDVQQLEwdHYWxpbGVv
MRMwEQYDVQQDEwpHYWxpbGVvIENBMRAwDgYDVQQpEwdFYXN5UlNBMS0wKwYJKoZI
hvcNAQkBFh5zdGVmYW5vLnNjaXBpb25pQGNzZ2FsaWxlby5vcmeCCQCiP4p3w6yw
KDAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQAYkF8O1NFJD0G5bJNn
hy4R7qStYnbELKFosI1KJ4Oz+ibYZxAOCOyURpacJq9NPYAS/P8SA4lHDjhe3ZIq
kNGq1ZxCHIsGWhagHFDHru2ct4nKtyEFSAzzy7UAnQITeTBZkEjDENWncdb41+VA
fJRoM8O1kj3+Kn0Zpwn126pp8/at3oyC4RMXM2FEztege5J93ZfogW/MuNyL4Jlv
iCGKzo/9UtjUGiHbuxUv7SimWYB4OAhrYR1t0sMLLJU7Bu012PEmxeyK6G1zJuBC
3/YQ9xlWkXlbp1E03OvBMCRp1AnJRsznZATBB4xnJ55ZPG6tEqCVS72j2fKMnCa2
vlW7
-----END CERTIFICATE-----
</ca>
lavagno.pem
-----BEGIN CERTIFICATE-----
MIIGATCCA+mgAwIBAgIJALHdThMpwfEhMA0GCSqGSIb3DQEBCwUAMIGWMQswCQYD
VQQGEwJJVDEOMAwGA1UECAwFSXRhbHkxDzANBgNVBAcMBlZlcm9uYTEXMBUGA1UE
CgwOQ29tdW5lIExhdmFnbm8xHjAcBgNVBAMMFWxhdmFnbm8uY3NnYWxpbGVvLm9y
ZzEtMCsGCSqGSIb3DQEJARYec3RlZmFuby5zY2lwaW9uaUBjc2dhbGlsZW8ub3Jn
MB4XDTE3MDIwODEzMDEzN1oXDTI3MDIwNjEzMDEzN1owgZYxCzAJBgNVBAYTAklU
MQ4wDAYDVQQIDAVJdGFseTEPMA0GA1UEBwwGVmVyb25hMRcwFQYDVQQKDA5Db211
bmUgTGF2YWdubzEeMBwGA1UEAwwVbGF2YWduby5jc2dhbGlsZW8ub3JnMS0wKwYJ
KoZIhvcNAQkBFh5zdGVmYW5vLnNjaXBpb25pQGNzZ2FsaWxlby5vcmcwggIiMA0G
CSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQCysUSjvroVYifgpS2Yc5q97GzlFUZw
9Fu04IZqrVXE8Mz8hsCsaGql0MmeMo7Y4TFL9gb6IvAv655mCRY3l3KzRzcyg94f
g4VB2SqjU3DhDtzZBUrBWo1v9P5oidftxVQbyUrrRJ6QUhlj4Ue1BZWUNd8ViTO9
xtnxUb8bz9XPxsf+GUajpA4w2cRGMX3N537dSYujcwSEsRTYndJubPDKcVJ6/3db
olH6Y3pB4o/K9/MttOGwRmeJIMsgxFxV/qhlEXQxNrwZOd9dpZvs83JOz+mHdd9j
36IBScGNQRHz+UcSOuek7YlgsP/bxiEOra1D22ZdE0620fMfXoupNEV1B/4CgmhS
IOTpJcRjKfPHmfpOpbDcIgw3QEmXcrW9K/sXihk5c7vN2mbiUyWtO6/Ihc8xmlUt
8Ilgvh1KSQ02IN9iObv4KAxL5dVZXmtku6H9LG6UfX/QxCg4/LH2RzwZcO0Al35R
3zn7FyOUKnvWrUuG/0hIiCoS4AgpTTIc9DCI5bA/YksOn8vz1SIklZ/vkjJ4LuxF
JkBgBCVl4b8ohOXR5Ecq1Q3Ai1AR/8n4b9ho50wqhioekRSQ6WjHLLn9XYQrEdCN
PXxulxnK7eiQtYD6Zn5A8MSvmfqUQ80QQsbMgO5YUt0lMxSX6qbZnItF76KYWSbD
72PFSDV24Lrg3wIDAQABo1AwTjAdBgNVHQ4EFgQUDke3u6KNfH6n+1S0wmUmWsB8
h18wHwYDVR0jBBgwFoAUDke3u6KNfH6n+1S0wmUmWsB8h18wDAYDVR0TBAUwAwEB
/zANBgkqhkiG9w0BAQsFAAOCAgEArtRfwcY2gER3s8uABZBWte0o5QMDVnbFxWdk
TE1knyOmhUj4tLvOs+sEjP4DHQRnKPpL86tccn3Z4ydS5mKNbbq1mNaslzvl66Zr
fdhExA3uahUexo8wJ8BXL3b7YdQ/AP6kIh2eZOslptj+BKzqQKgFKy9mqdv9jXM/
cseT6+zdt258u8dSSGDrBj/87f1HTUYt1wcjcN0g8l5v0x0YrcsjyBw/i6hkVZWy
bkByUTzuQSEJNZZwv7SHIDlZlXml0Sw1EoucrmxZAB2EsRLQfivbl536a711mgr8
DNof7+ttWpFBFb+U+G1ipDNhiBiAkhLJMSL7vB5JHcu/YLUgZiVXzOmD1YI812PJ
wECaqp7VfbdNb9kzkpTMTAZqtWg60h1wq+zS094VkNTvSO/Dy8dtukA3BMkI/bwY
fLAfq78Miu6KglFmJF2VSifxW7zynNIVe0DtXGmUOR16FKJfdwNxTZpmMZnPviRz
YNmyA6A0gwPolKfwEFsRth0oKdQyZqyOZeriKoHBOWXkDH26MqMBlNMAzPodORbK
YrXpcmIEOYSwJnMtW+rqfniH5mCYvq/SU+csDZr7uWgSMcY3im40f30JJ+ndYyig
aBZVSFSow2dELbQdqo1aA/JR1hUk05NExE6KAIc4JNrMzD4b4HxMPcc/yuYLKDb3
Hd9TG/E=
-----END CERTIFICATE-----

add VPN connection with network manager GUI:

  • type: openvpn
  • gateway: lavagno.csgalileo.org
  • user: galileo
  • pass: <pass>
  • CA certificate: <lavagno.pem>
  • in advanced settings check “Use TCP connection”
  • tips/vpn/galileo.1513250850.txt.gz
  • Last modified: 2017/12/14 12:27
  • by scipio